Skip to content

Legal

Privacy Policy

Effective date: October 9, 2026

The short version

  • Your code stays yours. We never sell it, and we never use it to train AI models.
  • We only access the repositories you explicitly authorize.
  • Our website uses no cookies, analytics, or ad trackers.
  • You can ask us to access or delete your data at any time.

GitDocu Inc. ("GitDocu," "we," "us," or "our") provides AI-assisted codebase documentation and pull request review tools. This Privacy Policy explains how we collect, use, share, and protect information when you visit gitdocu.com (the "Site"), contact us, or use our products, including our private beta (together, the "Services").

GitDocu is currently in private beta. As the Services evolve, we will keep this policy up to date and tell you about material changes as described in Section 11.

1. Information we collect

Information you give us

When you request early access, email us, or otherwise contact us, we collect the information you choose to share, such as your name, email address, company name, GitHub organization or repository, team size, the plan you are interested in, and the contents of your message.

Account and repository data

If you join the beta and connect GitHub, we collect:

  • GitHub account information, such as your username, user ID, avatar, and the email address associated with your account.
  • Organization and repository metadata, such as repository names, branches, pull request and commit metadata, and installation settings.
  • Customer Code, meaning the source code, pull request diffs, documentation, and other repository contents in the repositories you authorize GitDocu to access.

Information collected automatically

Our Site does not use cookies, analytics, or advertising trackers. When your browser loads the Site, our hosting provider and the third-party services that deliver our fonts and styling (Google Fonts and the Tailwind CSS content delivery network) receive standard technical information, such as your IP address, browser type, and the page requested. These providers handle that information under their own privacy policies. If we add analytics or cookies in the future, we will update this policy first.

2. How we use information

We use the information we collect to:

  • respond to your requests and manage the early access waitlist and beta program;
  • provide the Services, including analyzing Customer Code to generate pull request review comments, documentation, diagrams, and answers to your questions;
  • operate, maintain, secure, and debug the Services, and prevent fraud and abuse;
  • send you service-related messages and, if you agree, product updates (you can unsubscribe from non-essential emails at any time); and
  • comply with our legal obligations and enforce our Terms of Service.

We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use Customer Code to train artificial intelligence models.

3. How we handle your source code

  • You choose what we can access. GitDocu only accesses repositories you explicitly authorize. We request the minimum GitHub permissions needed: read access to repository contents and, where you enable those features, permission to post review comments and open documentation pull requests.
  • AI processing. To analyze your code, we send the relevant portions of Customer Code to Anthropic, PBC through the Claude API. We use the Claude API under Anthropic's Commercial Terms of Service, which govern how Anthropic handles that data.
  • No permanent copy of your repository. We process Customer Code to perform each analysis and do not keep a permanent copy of your repository.
  • What we do store. We store the results of our analysis, such as review findings and generated documentation. To power the Repo Knowledge Base, we may also store a search index of your repository, which can include code excerpts, for as long as that repository remains connected.
  • Disconnecting. If you disconnect a repository or delete your account, we delete the related index and stored analysis results as described in Section 5. Comments and pull requests we already posted to GitHub remain in your repository until you remove them.

4. How we share information

We share information only as described below:

  • Service providers. We use trusted vendors that process information on our behalf, including Anthropic (AI processing), GitHub (authentication and repository access), and our website hosting, cloud hosting, and email providers. They may use the information only to provide services to us, under contractual confidentiality and security obligations. A current list of these providers is available on request.
  • Legal requirements. We may disclose information if we believe in good faith that it is required by law, subpoena, or other legal process, or that it is necessary to protect the rights, property, or safety of GitDocu, our users, or others.
  • Business transfers. If GitDocu is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
  • With your consent. We may share information for other purposes when you ask us to or agree to it.

5. Data retention

  • Waitlist and contact information is kept until you ask us to delete it, and no longer than 24 months after our last communication with you.
  • Account data, stored analysis results, and repository indexes are kept while your account is active and deleted within 30 days after you disconnect the related repository or delete your account.
  • Backups containing this information are overwritten on a rolling basis within 90 days.

We may keep limited information longer when the law requires it, or to resolve disputes and enforce our agreements.

6. Security

We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit (TLS), encryption of stored data, and access controls that limit access to the people and systems that need it. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we learn of a security incident affecting your personal information, we will notify you as required by applicable law.

To report a security vulnerability, email contact@gitdocu.com with the subject line "Security Report."

7. Your rights and choices

Wherever you live, you can ask us to:

  • tell you what personal information we hold about you and give you a copy;
  • correct inaccurate information;
  • delete your information; and
  • stop sending you non-essential emails (you can also use the unsubscribe link in any marketing email).

To make a request, email contact@gitdocu.com with the subject line "Privacy Request." We will verify your identity, usually by confirming control of the email address or GitHub account associated with your data, and respond within 45 days. Residents of states with comprehensive privacy laws, such as Virginia, Colorado, Connecticut, Utah, and Texas, have these rights under state law. If we decline your request, you may appeal by replying to our decision, and we will respond to your appeal within the time required by your state's law.

Because we do not sell or share personal information, there is nothing to opt out of. We nevertheless honor Global Privacy Control (GPC) signals as an opt-out request.

8. California residents

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), gives you additional rights.

  • Categories we collect: identifiers (such as name, email address, and GitHub username); professional information (such as company and team size); internet activity information (such as the technical data described in Section 1); and the contents of messages and Customer Code you provide.
  • Sources: directly from you, from GitHub when you connect your account, and automatically when you use the Site.
  • Purposes: the business purposes described in Section 2.
  • Disclosures: we disclose these categories to the service providers described in Section 4 for business purposes. We do not sell or share personal information, as those terms are defined in the CCPA, and have not done so in the past 12 months.
  • Sensitive personal information: we do not use or disclose sensitive personal information for purposes that would give you a right to limit its use.
  • Your rights: you have the right to know, access, correct, and delete your personal information, and the right not to be discriminated against for exercising these rights. You can submit requests as described in Section 7, or through an authorized agent with your signed permission.

9. Children's privacy

The Services are intended for professional use and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, please contact us and we will delete it.

10. Users outside the United States

GitDocu is based in the United States, and we process and store information in the United States. If you use the Services from outside the United States, you understand that your information will be transferred to, and processed in, the United States, where data protection laws may differ from those in your country.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will change the effective date at the top of this page. If we make material changes, we will notify you by email or by a notice on the Site before the changes take effect.

12. Contact us

If you have questions about this Privacy Policy or our privacy practices, contact us at:

GitDocu Inc.
Email: contact@gitdocu.com